peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,108 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-4886 EXP Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote attackers to execute arbitrary PHP code via a (1) UNC sh… Patch early 6.8 medium 2.1% 2007-09-14
CVE-2007-5138 EXP PHP remote file inclusion vulnerability in forum/forum.php in lustig.cms BETA 2.5 allows remote attackers to execute arbitrary PHP code via a URL in t… Patch early 6.8 medium 2.1% 2007-09-28
CVE-2007-5139 EXP PHP remote file inclusion vulnerability in admin/include/header.php in chupix 0.2.3, when register_globals is enabled, allows remote attackers to exec… Patch early 6.8 medium 2.1% 2007-09-28
CVE-2007-5409 EXP PHP remote file inclusion vulnerability in admin/nuseo_admin_d.php in NuSEO PHP Enterprise 1.6 (NuSEO.PHP), when register_globals is enabled, allows r… Patch early 6.8 medium 2.1% 2007-10-12
CVE-2007-5627 EXP PHP remote file inclusion vulnerability in content/fnc-readmail3.php in SocketMail 2.2.8 allows remote attackers to execute arbitrary PHP code via a U… Patch early 6.8 medium 2.1% 2007-10-23
CVE-2007-5754 EXP PHP remote file inclusion vulnerability in urlinn_includes/config.php in phpFaber URLInn 2.0.5 allows remote attackers to execute arbitrary PHP code v… Patch early 6.8 medium 2.1% 2007-10-31
CVE-2007-5784 EXP PHP remote file inclusion vulnerability in index.php in CaupoShop Pro 2.x allows remote attackers to execute arbitrary PHP code via a URL in the actio… Patch early 6.8 medium 2.1% 2007-11-01
CVE-2007-6027 EXP PHP remote file inclusion vulnerability in admin.jjgallery.php in the Carousel Flash Image Gallery (com_jjgallery) component for Joomla! allows remote… Patch early 6.8 medium 2.1% 2007-11-20
CVE-2007-6139 EXP PHP remote file inclusion vulnerability in index.php in Mp3 ToolBox 1.0 beta 5 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 6.8 medium 2.1% 2007-11-27
CVE-2007-6464 EXP Multiple PHP remote file inclusion vulnerabilities in Form tools 1.5.0b allow remote attackers to execute arbitrary PHP code via a URL in the g_root_d… Patch early 6.8 medium 2.1% 2007-12-20
CVE-2006-5057 EXP Multiple cross-site scripting (XSS) vulnerabilities in Ktools.net PhotoStore allow remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 5.1 medium 2.1% 2006-09-28
CVE-2006-5064 EXP Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the… Patch early 5.1 medium 2.1% 2006-09-28
CVE-2006-5066 EXP Multiple cross-site scripting (XSS) vulnerabilities in DanPHPSupport 0.5, and other versions before 1.0, allow remote attackers to inject arbitrary we… Patch early 5.1 medium 2.1% 2006-09-28
CVE-2007-3939 EXP SQL injection vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) CMS 3.4 and earlier allows remote attackers to e… Patch early 6.8 medium 2.1% 2007-07-21
CVE-2013-6275 EXP Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php. Patch early 6.5 medium 2.1% 2019-11-05
CVE-2006-2497 EXP Multiple cross-site scripting (XSS) vulnerabilities in AspBB 0.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) action pa… Patch early 5.8 medium 2.1% 2006-05-20
CVE-2020-8839 EXP Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cgi TF_submask field. Patch early 6.1 medium 2.1% 2020-02-12
CVE-2007-6399 EXP index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current user account by reading the passw… Patch early 6.5 medium 2.1% 2007-12-17
CVE-2008-6282 EXP SQL injection vulnerability in engine/users/users_edit_pub.inc in CMS Ortus 1.13 and earlier allows remote authenticated users to execute arbitrary SQ… Patch early 6.5 medium 2.1% 2009-02-25
CVE-2007-4057 EXP Unrestricted file upload vulnerability in pfs.php in Neocrome Seditio 121 and earlier allows remote authenticated users to upload arbitrary PHP code v… Patch early 6.5 medium 2.1% 2007-07-30
CVE-2006-5722 EXP Multiple PHP remote file inclusion vulnerabilities in Segue CMS 1.5.9 and earlier, when magic_quotes_gpc is enabled, allow remote attackers to execute… Patch early 5.1 medium 2.1% 2006-11-04
CVE-2008-2881 EXP Relative Real Estate Systems 3.0 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sen… Patch early 5.0 medium 2.1% 2008-06-26
CVE-2007-3429 EXP Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload a… Patch early 6.8 medium 2.1% 2007-06-27
CVE-2018-5479 EXP FoxSash ImgHosting 1.5 (according to footer information) is vulnerable to XSS attacks. The affected function is its search engine via the search param… Patch early 6.1 medium 2.1% 2018-01-15
CVE-2006-1828 EXP SQL injection vulnerability in php121language.php in PHP121 1.4 allows remote attackers to execute arbitrary SQL commands and execute arbitrary code v… Patch early 5.1 medium 2.1% 2006-04-19
CVE-2003-1436 EXP PHP remote file inclusion vulnerability in nukebrowser.php in Nukebrowser 2.1 to 2.5 allows remote attackers to execute arbitrary PHP code via the fil… Patch early 6.8 medium 2.1% 2003-12-31
CVE-2005-1051 EXP SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in… Patch early 6.5 medium 2.1% 2005-05-02
CVE-2013-5716 EXP Gretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a crafted WAV f… Patch early 4.3 medium 2.1% 2013-09-09
CVE-2006-7100 EXP PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Insert User 0.1.2 and earlier allows remote attackers to execute a… Patch early 6.8 medium 2.1% 2007-03-03
CVE-2006-2459 EXP SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL commands via… Patch early 6.4 medium 2.1% 2006-05-19
← previous page 234 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt